2.18 Ensure 'Whether online OCSP/CRL checks are required for local trust anchors' is set to 'Enabled'

Information

Google Chrome performs revocation checking for server certificates that successfully validate and are signed by locally-installed CA certificates. If Google Chrome is unable to obtain revocation status information, such certificates will be treated as revoked ('hard-fail').
Rationale:
Certificates shall always be validated.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled:
Computer Configuration\Administrative Templates\Google\Google Chrome\Whether online OCSP/CRL checks are required for local trust anchors
Impact:
A revocation check will be performed for server certificates that successfully validate and are signed by locally-installed CA certificates. if the OCSP server goes down, then this will hard-fail and prevent browsing to those sites.
Default Value:
Disabled. Google Chrome will use the existing online revocation checking settings.

See Also

https://workbench.cisecurity.org/files/2385

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-23(5), CSCv7|7

Plugin: Windows

Control ID: 3afd126c928c1892f96b5dae8df24f578a72e29140e94562fcc61b4f42856586